IP Library Granted Patent US 12,330,772
Granted Patent B1
US 12,330,772 · App. 18/813,435 · Granted Jun 17, 2025

Fault-tolerant multi-processor systems and methods for an aircraft

Inventors: Scott Furman (Menlo Park, CA); Fernanda Aline Matta De Paiva (Los Altos Hills, CA); Sergio Henrique Soares Ferreira (San Jose, CA); Guy Bernard (Kirkland, CA); Damien Bardon (San Jose, CA)
Assignee: Archer Aviation Inc.
B64C19/00B64F5/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,330,772
App. No.
18/813,435
Granted
Jun 17, 2025
Kind
B1
Abstract

Aspects of the present disclosure generally relate to systems and methods for flight control of aircrafts driven by electric propulsion systems and in other types of vehicles. In some embodiments, a computer-implemented method for controlling an aircraft is disclosed, comprising: receiving, from a source processor, a first copy of a signal corresponding to an input device; sending a second copy of the signal to all other processors; receiving a number of second copies of the signal from all other processors, the number of second copies being equal to the number of all other processors excluding the source processor; determining a consensus signal based on the first copy and the second copies of the signal; and determining a command signal for an effector of the aircraft based on the consensus signal, and wherein no two processors are configured to receive signals from a same input device.

Claims (90)

1. A signal-processing multi-processor system for an aircraft, comprising:

a plurality of processors, wherein each processor is configured to perform operations comprising:

receiving, from a source processor among the plurality of the processors, a first copy of a signal corresponding to an input device;

sending a second copy of the signal to all other processors of the plurality excluding the source processor, wherein the second copy of the signal is substantially identical to the first copy of the signal;

receiving a number of second copies of the signal from all other processors of the plurality excluding the source processor, the number of second copies being equal to the number of all other processors of the plurality excluding the source processor;

determining a consensus signal based on the first copy and the second copies of the signal; and

determining a command signal for an effector of the aircraft based on the consensus signal, and

wherein no two processors of the plurality receive the signal from a same input device.

2. The system of claim 1 , wherein determining the consensus signal comprises inputting all received copies of the signal to an exact consensus agreement algorithm.

3. The system of claim 2 , wherein the exact consensus agreement algorithm determines the consensus signal by outputting a mode of respective datasets encoded by the first copy and the second copies of the signal.

4. The system of claim 1 , wherein determining the command signal comprises inputting the consensus signal to a control law algorithm.

5. The system of claim 4 , wherein the control law algorithm determines at least one of a thrust command or an effector position based on the consensus signal.

6. The system of claim 1 , further comprising:

the effector,

wherein the plurality of processors comprise:

a first pair of processors comprising a first command processor and a first monitor processor; and

a second pair of processors comprising a second command processor and a second monitor processor,

wherein the effector is configured to act based on the command signal received from the first pair of processors.

7. The system of claim 6 , wherein each monitor processor is configured to:

compare a first command signal generated by a corresponding command processor with a second command signal generated by the monitor processor; and

in response to determining the first command signal differs from the second command signal, inhibit the corresponding command processor.

8. The system of claim 7 wherein the effector is further configured to act based on the command signal received from the second pair of processors after determining the first command processor is inhibited.

9. The system of claim 6 , wherein the effector is further configured to:

receive the command signal;

determine if the command signal is classified as reversible or not reversible;

if the command signal is classified as reversible:

act based on the command signal after receiving only a single copy of the command signal; and

if the command signal is classified as not reversible:

act based on the command signal only after receiving multiple copies of the command signal.

10. The system of claim 9 , wherein determining a classification of the command signal is based on a data structure stored in a memory component of the effector.

11. The system of claim 1 , wherein two or more input devices of a same type are each connected to a different processor of the plurality of processors.

12. A computer-implemented method for controlling an aircraft, comprising:

receiving, from a source processor among a plurality of processors, a first copy of a signal corresponding to an input device;

sending a second copy of the signal to all other processors of the plurality excluding the source processor, wherein the second copy of the signal is substantially identical to the first copy of the signal;

receiving a number of second copies of the signal from all other processors of the plurality excluding the source processor, the number of second copies being equal to the number of all other processors of the plurality excluding the source processor;

determining a consensus signal based on the first copy and the second copies of the signal; and

determining a command signal for an effector of the aircraft based on the consensus signal, and

wherein no two processors of the plurality receive the signal from a same input device.

13. The computer-implemented method of claim 12 , wherein:

determining the consensus signal comprises inputting all received copies of the signal to an exact consensus agreement algorithm, and

the exact consensus agreement algorithm determines the consensus signal by outputting a mode of respective datasets encoded by the first copy and the second copies of the signal.

14. The computer-implemented method of claim 12 , wherein:

determining the command signal comprises inputting the consensus signal to a control law algorithm, and

the control law algorithm determines at least one of a thrust command or an effector position based on the consensus signal.

15. The computer-implemented method of claim 12 , further comprising:

the effector,

wherein the plurality of processors comprise:

a first pair of processors comprising a first command processor and a first monitor processor; and

a second pair of processors comprising a second command processor and a second monitor processor,

wherein the effector is configured to act based on the command signal received from the first pair of processors.

16. The computer-implemented method of claim 15 , wherein each monitor processor is configured to:

compare a first command signal generated by a corresponding command processor with a second command signal generated by the monitor processor; and

in response to determining the first command signal differs from the second command signal, inhibit the corresponding command processor.

17. The computer-implemented method of claim 16 , wherein the effector is further configured to act based on the command signal received from the second pair of processors after determining the first command processor is inhibited.

18. The computer-implemented method of claim 15 , wherein the effector is further configured to:

receive the command signal;

determine if the command signal is classified as reversible or not reversible;

if the command signal is classified as reversible:

act based on the command signal after receiving only a single copy of the command signal; and

if the command signal is classified as not reversible:

act based on the command signal only after receiving multiple copies of the command signal.

19. The computer-implemented method of claim 18 , wherein determining a classification of the command signal is based on a data structure stored in a memory component of the effector.

20. The computer-implemented method of claim 12 , wherein two or more input devices of a same type are each connected to a different processor of the plurality of processors.

21. A signal-processing multi-processor system for an aircraft, comprising:

a first pair of processors comprising a first command processor and a first monitor processor;

a second pair of processors comprising a second command processor and a second monitor processor; and

an effector configured to act based on the command signal received from the first pair of processors,

wherein each monitor processor is configured to:

compare a first command signal generated by a corresponding command processor with a second command signal generated by the monitor processor; and

in response to determining the first command signal differs from the second command signal, inhibit the corresponding command processor.

22. The system of claim 21 , wherein the effector is further configured to act based on the command signal received from the second pair of processors after determining the first command processor is inhibited.

23. The system of claim 21 , wherein the effector is further configured to:

receive the command signal;

determine if the command signal is classified as reversible or not reversible;

if the command signal is classified as reversible:

act based on the command signal after receiving only a single copy of the command signal; and

if the command signal is classified as not reversible:

act based on the command signal only after receiving multiple copies of the command signal.

24. The system of claim 23 , wherein determining a classification of the command signal is based on a data structure stored in a memory component of the effector.

25. The system of claim 21 , wherein each processor is configured to perform operations comprising:

receiving, from a source processor among the plurality of the processors, a first copy of a signal corresponding to an input device;

sending a second copy of the signal to all other processors of the plurality excluding the source processor, wherein the second copy of the signal is substantially identical to the first copy of the signal;

receiving a number of second copies of the signal from all other processors of the plurality excluding the source processor, the number of second copies being equal to the number of all other processors of the plurality excluding the source processor;

determining a consensus signal based on the first copy and the second copies of the signal; and

determining a command signal for the effector of the aircraft based on the consensus signal, wherein no two processors of the plurality receive the signal from a same input device.

26. The system of claim 25 , wherein determining the consensus signal comprises inputting all received copies of the signal to an exact consensus agreement algorithm.

27. The system of claim 26 , wherein the exact consensus agreement algorithm determines the consensus signal by outputting a mode of respective datasets encoded by the received first copy and the second copies of the signal.

28. The system of claim 25 , wherein determining the command signal comprises inputting the consensus signal to a control law algorithm.

29. The system of claim 28 , wherein the control law algorithm determines at least one of a thrust command or an effector position based on the consensus signal.

30. The system of claim 25 , wherein two or more input devices of a same type are each connected to a different processor of the plurality of processors.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME PREVIOUSLY RECORDED AT REEL: 68382 FRAME: 407. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 30, 2026
From: FURMAN, SCOTT; DE PAIVA, FERNANDA ALINE MATTA; FERREIRA, SERGIO HENRIQUE SOARES; BERNARD, GUY; BARDON, DAMIEN
To: ARCHER AVIATION INC.
Reel/Frame 075311/0221 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2024
From: FURMAN, SCOTT; DE PAIVA, FERNANDA ALINE MATTA; FERREIRA, SERGIO HENRIQUE SOARES; BERNARD, GUY; BARDON, DAMIEN
To: ARCHER AVIATION INC.
Reel/Frame 068382/0407 →
References Cited (34)
US 4015246A · Hopkins, Jr. · 1977 [cited by examiner]
US 4583224A · Ishii · 1986 [cited by examiner]
US 4907232A · Harper · 1990 [cited by examiner]
US 5001646A · Caldwell et al. · 1991 [cited by applicant]
US 5598529A · Garay · 1997 [cited by examiner]
US 9898033B1 · Long · 2018 [cited by applicant]
US 11323214B2 · MacAfee · 2022 [cited by examiner]
US 11757382B2 · Mores et al. · 2023 [cited by applicant]
US 11822330B2 · Stephan et al. · 2023 [cited by applicant]
US 11866195B2 · Yuksel et al. · 2024 [cited by applicant]
US 11939041B2 · Zwiener et al. · 2024 [cited by applicant]
US 20020153452A1 · King et al. · 2002 [cited by applicant]
US 20040093130A1 · Osder et al. · 2004 [cited by applicant]
US 20100076625A1 · Yoeli · 2010 [cited by applicant]
US 20130138270A1 · Christensen et al. · 2013 [cited by applicant]
US 20150120009A1 · Killian · 2015 [cited by examiner]
US 20190332125A1 · Irwin, III et al. · 2019 [cited by applicant]
US 20200333805A1 · English et al. · 2020 [cited by applicant]
US 20240310850A1 · Stephan · 2024 [cited by applicant]
EP 3891067B1 · 2024 [cited by applicant]
WO 2020180373A2 · 2020 [cited by applicant]
Advanced Avion (Year: 1977). [cited by examiner]
Lala et al. (1994). Architectural principles for safety-critical real-time applications. Proceedings of the IEEE, 82(1), 25-40. https://doi.org/10.1109/5.259424. [cited by applicant]
Nayak et al. (2019). Authenticated Synchronous BFT. Github.io. https://decentralizedthoughts.github.io/2019-11-11-authenticated-synchronous-bft/. [cited by applicant]
Ulrich et al. (2003). Formally verified Byzantine agreement in presence of link faults. https://doi.org/10.1109/icdcs.2002.1022311. [cited by applicant]
Loveless et al. (2021). IGOR: Accelerating Byzantine Fault Tolerance for Real-Time Systems with Eager Execution. https://doi.org/10.1109/rtas52030.2021.00036. [cited by applicant]
Pease et al. (1980). Reaching Agreement in the Presence of Faults. Journal of the ACM, 27(2), 228-234. https://doi.org/10.1145/322186.322188. [cited by applicant]
Biely et al. (2011). Synchronous consensus under hybrid process and link failures. Theoretical Computer Science, 412(40), 5602-5630. https://doi.org/10.1016/j.tcs.2010.09.032. [cited by applicant]
Schneider (2006). The State Machine Approach: A Tutorial. Springer EBooks, 18-41. https://doi.org/10.1007/bfb0042323. [cited by applicant]
Walker, G., et al., “F-35B Integrated Flight-Propulsion Control Development”, 2013 international powered lift conference, 2013, 15 pages. [cited by applicant]
Vigano, L., et al., “Development of augmented control laws for a tilt rotor in low and high speed flight modes”, European Rotorcraft Forum, 2017, 14 pages. [cited by applicant]
Denham, J., et al., “Converging on a precision Hover control strategy for the F-35B Stovl aircraft.”, AIAA Guidance, Navigation and Control Conference and Exhibit, 2006, 13 pages. [cited by applicant]
Whittle, R., “Flying The Osprey Is Not Dangerous, Just Different: Veteran Pilots”, Breaking Defense, Sep. 5, 2012, 11 pages. [cited by applicant]
Kang, Y., et al., “Development of flight control system and troubleshooting on flight test of a tilt-rotor unmanned aerial vehicle”, International Journal of Aeronautical and Space Sciences 17.1, 2016, p. 120-131, 12 pa… [cited by applicant]
Cited By (4)
US 1,115,657 US 1,139,034 US 1,146,758 US 12,498,719